WordPress Maintenance & Security
A WordPress website is never "finished". It has to be continuously maintained and hardened against new security vulnerabilities. We take over the maintenance of your WordPress site completely, from automated updates through backups to rapid intervention if things do catch fire.
Ongoing maintenance: updates, backups, monitoring
WordPress itself, your theme and every installed plugin receive regular updates, including security-relevant ones. If these are skipped, open vulnerabilities pile up over months, which is exactly what makes WordPress a popular target. We apply updates in a controlled way, test them beforehand on a staging environment and keep a continuous eye on your site, including automated, regular backups so a clean restore point is ready in an emergency.
For us, maintenance also includes monitoring. We watch your site's availability, load times and unusual behaviour, so problems get noticed before they reach your visitors. For load times we use our own free tool SiteSentry, which monitors PageSpeed automatically and raises the alarm when a plugin update has made the site slower. All of this runs as a classic WordPress maintenance contract, with a guaranteed scope instead of vague aspiration.
Security plugins in use
Alongside our own processes, where it makes sense we rely on proven security plugins like Wordfence or Sucuri. They continuously monitor your installation for suspicious file changes, block automated attack attempts and raise the alarm as soon as something doesn't belong in your WordPress directory.
A security plugin is no substitute for real maintenance, though. It's an additional building block, not a replacement for current versions, clean user permissions and a watchful eye on your website.
Security: prevent instead of repair
Most successful attacks on WordPress sites exploit known, long-since-patched vulnerabilities in outdated plugins or themes. The most effective protection is therefore not being attackable in the first place: current versions, a lean plugin selection, restrictive user permissions and a login area that doesn't lie open to automated brute-force attempts.
What belongs to our security concept
- Web application firewall and protection against automated brute-force login attempts
- Regular security scans for malicious code and manipulated files
- Encrypted connections (SSL/TLS) and cleanly configured HTTP security headers
- Restrictive file and user permissions instead of WordPress default settings
- Separate, encrypted backups outside the actual hosting environment
WordPress hacked or site down? Immediate help
If your site is already compromised (redirects to foreign domains, a Google warning, unknown admin accounts or simply a bad feeling), one thing counts above all: fast and considered action instead of panic. If necessary we take the site offline immediately, preserve the current state for analysis, identify the entry point and remove malicious code without residue, instead of merely papering over symptoms.
What you can do in the first few minutes
- Change the passwords, for the WordPress admin, hosting, FTP and the database. A new password alone does not close the hole, but it cuts off ongoing access.
- Overwrite nothing: do not restore a backup before the current state is preserved, otherwise the traces are gone and the cause stays open.
- Delete nothing: please leave suspicious files and user accounts where they are, they are part of the analysis.
- Tell your hosting provider, in case a suspension or an abuse notice has already come from there.
- Note down what you spotted and when. The timing narrows things down considerably.
We take on the clean-up even if we have not looked after your site before. An existing contract is not a requirement.
After that we close the exploited gap, renew compromised credentials and accompany you through recovery if your site has been flagged as unsafe by Google. Then we set up ongoing maintenance and monitoring, so it never gets that far next time.
How a hack usually shows itself first
- Unexpected redirects to foreign domains or spam content on your site
- New, unknown users in the WordPress backend
- Unusually high server load without a discernible reason
- A Google warning that your website might be unsafe
For the clean-up we often take a radical but reliable route: the WordPress core folders wp-admin and wp-includes are completely replaced with fresh, official files, since they contain no custom content anyway. Particular attention goes to the uploads folder: it's writable and thus a popular entry point; executable files have absolutely no business being there.
Not every outage is a hack
When a site suddenly stays white or stops loading at all, the first thought is often an attack. Usually something more harmless is behind it, an update that went wrong or a memory limit at its ceiling. Knowing the symptom helps with the diagnosis. We look at both, the suspected attack and the technical fault.
Common failure patterns and what is usually behind them
- White page with no error message: almost always a PHP error after an update, often a memory limit set too low or a plugin conflict.
- Error establishing a database connection: the database is overloaded or offline, less often the credentials in wp-config.php have changed. That last one would be a warning sign.
- Subpages return 404 while the homepage works: usually lost permalink rules, for instance after a move or a server change.
- Changes do not show up: as a rule a caching problem at server, plugin or browser level.
- Uploads fail: file permissions, disk space or an upload limit on the server that is set too small.
Some of this you can fix yourself with a bit of technical understanding. Once you start wondering whether a file has been tampered with, you have reached the point where it is better to call someone in than to keep trying things.
Frequently asked questions in an emergency
My WordPress site has been hacked, what do I do first?
Can you help if I am not a client?
Should I just restore a backup?
Google is warning about my site, how do I get out of that?
How long does a clean-up take?
My site is white or unreachable, is that a hack?
Related topics
WordPress hosting
Reliable hosting is the basis of every security strategy. More on our WordPress hosting.
WordPress training
Admin training for your team ensures basic security rules are actually followed day to day. More on our WordPress training.
WordPress SEO
A Google security warning also affects your visibility in search. More on WordPress SEO.
Plugins in the multisite network
Every plugin lying unused in the network is attack surface and update effort. How to keep the overview in a multisite.
Ready for your WordPress project?
Tell us about your project. We'll get back to you promptly with an honest assessment.